- SituationOn-premises Windows estate · remote desktop and data services · collaboration outside Microsoft · Azure tenant already present
- RiskLicensing and migration treated as one purchase · endpoints and identity not ready for the workloads · compliance controls arriving after the data
- OutcomePhased roadmap · early track for hybrid devices · licensing tied to the phase that can use it · acceptance criteria before anyone calls a phase done
The situation
The organization could describe its servers, its databases, and how people reached applications through remote desktop. What it did not have was an order of operations. Directory sync, always-on remote access, hybrid join, Intune, and patching are prerequisites. They are not cleanup you do after the file server has already moved.
There was also a licensing temptation: buy the bundle that includes every control, then figure out operations. Controls you cannot run are cost, not resilience.
What we did
- Inventoried identity, endpoints, file and database services, and remote desktop use from what the client could already show — no invented capacity plan
- Split an early track from the later workload moves: directory sync, remote connectivity, domain join for remote PCs, then Intune and quality patching
- Put gates in front of device enrollment so sync and remote access were working before Intune became the management plane
- Ordered the rest: tenant and landing zone, security and compliance control plane, collaboration migration, endpoint management, data and application workloads, virtualization transition, then decommission
- Tied licensing to those phases, with an out-of-scope list and acceptance criteria so a phase could be called done
Results
Leadership had a sequence they could fund and staff. The early track could start without pretending the servers had already moved. Later phases — file services, databases, web, remote desktop, directory, and the hypervisor — stayed in an order that does not strand the last administrator.
The deliverable was the roadmap, the gates, and the acceptance criteria. It was not a finished migration, and the write-up does not claim one. Client identity is withheld. The pattern is one we repeat: make identity and the device plane real, then move workloads.
Related
See our Microsoft Azure, Managed IT, and Virtualization practices, or contact us if a Microsoft migration is being planned as a license purchase.
Ready to talk through the next step?
Projects, managed services, or an honest read on your environment. You reach a principal consultant.